Common Criteria

Common Criteria (CC) is an international standard (ISO/IEC 15408) for evaluating and certifying the security properties of IT products, giving buyers a repeatable way to judge whether a product meets its stated security claims. It replaced older national schemes such as the U.S. Orange Book.

An evaluation revolves around a few key artifacts. The Target of Evaluation is the product under review, the Protection Profile is a standardized set of security requirements for a class of products, and the Security Target states exactly what the specific product claims to do. The result is expressed as an Evaluation Assurance Level from EAL1 to EAL7, where a higher number means more thorough testing was performed. A point that trips people up is that EAL measures the depth of assurance, not how secure the product is; a high EAL only confirms the evaluated claims were tested, and says nothing about functionality outside the Security Target. Certification is also tied to a specific configuration, so a product used differently may not carry the same assurance.

Why does Common Criteria matter for the CISSP exam?

Common Criteria sits in Domain 3 (Security Architecture and Engineering), weighted at 13%. Know EAL levels, Protection Profiles, and what assurance really certifies. Review Domain 3 Security Architecture and Engineering for the evaluation models.